clud-bug-collaboration
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [SAFE]: The skill serves as a documentation and instruction set for integrating AI agents with the 'clud-bug' PR review bot. It includes safety-oriented instructions, such as prohibiting the agent from overriding security gates (strict mode) and explaining the security implications of modifying GitHub workflow files.
- [EXTERNAL_DOWNLOADS]: The skill references external resources including the clud-bug website (cludbug.dev) and official GitHub repositories under the 'thrillmade' and 'anthropics' organizations. These resources are consistent with the skill's stated purpose and author context.
- [COMMAND_EXECUTION]: The skill describes the use of the
clud-bugCLI tool for repository configuration, skill management, and updates. These commands are documented as standard operational procedures for the tool. - [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process data from external PR review comments.
- Ingestion points: GitHub Pull Request review comments posted by the
clud-bugbot. - Boundary markers: The skill defines specific triage prefixes (emoji severity) to identify valid findings.
- Capability inventory: No direct unsafe capabilities are defined in the skill itself; it focuses on interpreting bot feedback.
- Sanitization: None specified for the content of the review comments.
Audit Metadata